Vendor
critical
advisory
Unauthenticated Remote Code Execution in DB-GPT via Path Traversal
1 rule 2 TTPs 1 CVEAn unauthenticated path traversal vulnerability in DB-GPT allows remote attackers to write arbitrary files and achieve remote code execution by uploading malicious Python modules to the application server.
DB-GPT
vulnerability
rce
path-traversal
webserver
1r
2t
1c
critical
advisory
Unauthenticated Path Traversal in DB-GPT
1 rule 1 TTP 1 CVEDB-GPT version 0.8.1 is vulnerable to an unauthenticated path traversal attack allowing remote code execution via a crafted user_id HTTP header.
PoC
DB-GPT
web-application-vulnerability
path-traversal
rce
1r
1t
1c
updated